mirror of
https://github.com/DayuanJiang/next-ai-draw-io.git
synced 2026-09-08 12:20:20 +08:00
test: add unit tests for baseURL isolation logic
Add comprehensive tests for the resolveBaseURL utility function: - Tests for user-provided API key scenarios - Tests for server credential scenarios - Edge case tests for empty strings and undefined values This addresses the Copilot review suggestion to add test coverage for the critical security fix.
This commit is contained in:
@@ -62,6 +62,32 @@ const ANTHROPIC_BETA_HEADERS = {
|
||||
"anthropic-beta": "fine-grained-tool-streaming-2025-05-14",
|
||||
}
|
||||
|
||||
/**
|
||||
* Resolve baseURL based on whether user is providing their own API key.
|
||||
* When user provides their own API key, we should NOT fall back to server's
|
||||
* baseURL environment variable - user credentials should only be sent to
|
||||
* user-specified endpoints or official provider endpoints.
|
||||
*
|
||||
* @param userApiKey - User-provided API key (if any)
|
||||
* @param userBaseUrl - User-provided base URL (if any)
|
||||
* @param serverBaseUrl - Server's base URL from environment variable
|
||||
* @param defaultBaseUrl - Provider's official/default base URL (optional)
|
||||
* @returns The resolved base URL to use
|
||||
*/
|
||||
export function resolveBaseURL(
|
||||
userApiKey: string | null | undefined,
|
||||
userBaseUrl: string | null | undefined,
|
||||
serverBaseUrl: string | undefined,
|
||||
defaultBaseUrl?: string,
|
||||
): string | undefined {
|
||||
if (userApiKey) {
|
||||
// User provides their own API key - only use user's baseUrl or default
|
||||
return userBaseUrl || defaultBaseUrl || undefined
|
||||
}
|
||||
// No user API key - fall back to server config
|
||||
return userBaseUrl || serverBaseUrl || defaultBaseUrl || undefined
|
||||
}
|
||||
|
||||
/**
|
||||
* Safely parse integer from environment variable with validation
|
||||
*/
|
||||
|
||||
@@ -1,5 +1,141 @@
|
||||
import { describe, expect, it } from "vitest"
|
||||
import { supportsImageInput, supportsPromptCaching } from "@/lib/ai-providers"
|
||||
import {
|
||||
resolveBaseURL,
|
||||
supportsImageInput,
|
||||
supportsPromptCaching,
|
||||
} from "@/lib/ai-providers"
|
||||
|
||||
describe("resolveBaseURL", () => {
|
||||
const SERVER_BASE_URL = "https://server-proxy.example.com"
|
||||
const USER_BASE_URL = "https://user-proxy.example.com"
|
||||
const DEFAULT_BASE_URL = "https://api.provider.com/v1"
|
||||
const USER_API_KEY = "user-api-key-123"
|
||||
|
||||
describe("when user provides their own API key", () => {
|
||||
it("uses user's baseUrl when provided", () => {
|
||||
const result = resolveBaseURL(
|
||||
USER_API_KEY,
|
||||
USER_BASE_URL,
|
||||
SERVER_BASE_URL,
|
||||
DEFAULT_BASE_URL,
|
||||
)
|
||||
expect(result).toBe(USER_BASE_URL)
|
||||
})
|
||||
|
||||
it("uses default baseUrl when user provides no baseUrl", () => {
|
||||
const result = resolveBaseURL(
|
||||
USER_API_KEY,
|
||||
null,
|
||||
SERVER_BASE_URL,
|
||||
DEFAULT_BASE_URL,
|
||||
)
|
||||
expect(result).toBe(DEFAULT_BASE_URL)
|
||||
})
|
||||
|
||||
it("returns undefined when user provides no baseUrl and no default exists", () => {
|
||||
const result = resolveBaseURL(
|
||||
USER_API_KEY,
|
||||
null,
|
||||
SERVER_BASE_URL,
|
||||
undefined,
|
||||
)
|
||||
expect(result).toBeUndefined()
|
||||
})
|
||||
|
||||
it("does NOT use server's baseUrl even when available", () => {
|
||||
const result = resolveBaseURL(
|
||||
USER_API_KEY,
|
||||
undefined,
|
||||
SERVER_BASE_URL,
|
||||
undefined,
|
||||
)
|
||||
// Should NOT return SERVER_BASE_URL
|
||||
expect(result).not.toBe(SERVER_BASE_URL)
|
||||
expect(result).toBeUndefined()
|
||||
})
|
||||
|
||||
it("prefers user's baseUrl over default", () => {
|
||||
const result = resolveBaseURL(
|
||||
USER_API_KEY,
|
||||
USER_BASE_URL,
|
||||
SERVER_BASE_URL,
|
||||
DEFAULT_BASE_URL,
|
||||
)
|
||||
expect(result).toBe(USER_BASE_URL)
|
||||
})
|
||||
})
|
||||
|
||||
describe("when using server credentials (no user API key)", () => {
|
||||
it("uses user's baseUrl when provided (overrides server)", () => {
|
||||
const result = resolveBaseURL(
|
||||
null,
|
||||
USER_BASE_URL,
|
||||
SERVER_BASE_URL,
|
||||
DEFAULT_BASE_URL,
|
||||
)
|
||||
expect(result).toBe(USER_BASE_URL)
|
||||
})
|
||||
|
||||
it("falls back to server's baseUrl when no user baseUrl", () => {
|
||||
const result = resolveBaseURL(
|
||||
null,
|
||||
null,
|
||||
SERVER_BASE_URL,
|
||||
DEFAULT_BASE_URL,
|
||||
)
|
||||
expect(result).toBe(SERVER_BASE_URL)
|
||||
})
|
||||
|
||||
it("falls back to default when no user or server baseUrl", () => {
|
||||
const result = resolveBaseURL(
|
||||
null,
|
||||
null,
|
||||
undefined,
|
||||
DEFAULT_BASE_URL,
|
||||
)
|
||||
expect(result).toBe(DEFAULT_BASE_URL)
|
||||
})
|
||||
|
||||
it("returns undefined when no baseUrl available anywhere", () => {
|
||||
const result = resolveBaseURL(null, null, undefined, undefined)
|
||||
expect(result).toBeUndefined()
|
||||
})
|
||||
|
||||
it("handles undefined apiKey same as null", () => {
|
||||
const result = resolveBaseURL(
|
||||
undefined,
|
||||
null,
|
||||
SERVER_BASE_URL,
|
||||
DEFAULT_BASE_URL,
|
||||
)
|
||||
expect(result).toBe(SERVER_BASE_URL)
|
||||
})
|
||||
})
|
||||
|
||||
describe("edge cases", () => {
|
||||
it("handles empty string apiKey as falsy (uses server config)", () => {
|
||||
const result = resolveBaseURL(
|
||||
"",
|
||||
null,
|
||||
SERVER_BASE_URL,
|
||||
DEFAULT_BASE_URL,
|
||||
)
|
||||
// Empty string is falsy, so should use server config
|
||||
expect(result).toBe(SERVER_BASE_URL)
|
||||
})
|
||||
|
||||
it("handles empty string baseUrl as falsy", () => {
|
||||
const result = resolveBaseURL(
|
||||
USER_API_KEY,
|
||||
"",
|
||||
SERVER_BASE_URL,
|
||||
DEFAULT_BASE_URL,
|
||||
)
|
||||
// Empty string baseUrl is falsy, should fall back to default
|
||||
expect(result).toBe(DEFAULT_BASE_URL)
|
||||
})
|
||||
})
|
||||
})
|
||||
|
||||
describe("supportsPromptCaching", () => {
|
||||
it("returns true for Claude models", () => {
|
||||
|
||||
Reference in New Issue
Block a user